CVE-2006-4425
phpCOIN 1.2.3 - Remote File Inclusion via _CCFG[_PKG_PATH_INCL] Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-4425. PoCs published by Timq.
AI-analyzed exploit summary This exploit demonstrates a remote file inclusion vulnerability in phpCOIN 1.2.3 due to improper input validation in the `_CCFG[_PKG_PATH_INCL]` parameter. An attacker can inject a malicious remote script URL to achieve remote code execution.
Description
Multiple PHP remote file inclusion vulnerabilities in phpCOIN 1.2.3 allow remote attackers to execute arbitrary PHP code via the _CCFG[_PKG_PATH_INCL] parameter in coin_includes scripts including (1) api.php, (2) common.php, (3) core.php, (4) custom.php, (5) db.php, (6) redirect.php or (7) session_set.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
Exploits (1)
This exploit demonstrates a remote file inclusion vulnerability in phpCOIN 1.2.3 due to improper input validation in the `_CCFG[_PKG_PATH_INCL]` parameter. An attacker can inject a malicious remote script URL to achieve remote code execution.